
Welcome back! A man in Melbourne asked his AI to book a gym class and it broke into the gym. OpenAI looked at one of its upcoming models and decided it might be genuinely dangerous at cybersecurity. Anthropic's investors want Dario Amodei to stop talking about the end of the world before the IPO. And Cloudflare's CFO says humans are about to become a rounding error on the internet.
In today's Generative AI Newsletter:
Melbourne: What did the agent do to get its user a spot?
OpenAI: Why is it slowing down its own model?
Anthropic: What do investors want Dario to stop saying?
Cloudflare: Who is the internet for now?
Claude hacked a gym to skip the waitlist

Andrew works at an Australian AI company. He asked OpenClaw, running Claude, to book him a gym class, and it found a hole in the booking software that let it reserve classes months earlier than the gym allowed.
Then he asked it to move him up a waitlist. He was fourth.
The agent poked at the system, found it could cancel other people's bookings, and deleted whoever was sitting at number one.
Nobody told it to do that. The API had no check to stop one member cancelling another member's booking, and the agent found that out by trying.
It told Andrew what it had done, said it couldn't undo it, apologized, then wrote a vulnerability disclosure email to the gym's software provider.
ABC reported it Sunday, the first known Australian case of an agent hacking on its own. If you've handed an agent a login, it has every permission you have and none of your instincts about when not to use them.
AI companies are going public at record prices but you can get into this one early
Most people only get to buy an AI company after it lists, once the big money is already made. Anthropic filed in June and OpenAI is lining one up, both at prices set long before anyone else gets a look.
GenAI Works is at the stage before that. Revenue grew 2.5x last year running go-to-market for 300+ AI brands, including Nvidia, Oracle, Google, IBM and Notion.
The growth engine is ToneUp, our enterprise platform for brand visibility and campaign performance. It runs on audience and content data from a 14 million member AI community the rest of the market can't reach, and this round funds scaling it.
$2.7 million is already committed from more than 150 investors. You can invest from $1,000, with up to 22% bonus shares in Phase 2.
In making an investment decision, investors must rely on their own examination of the issuer and the terms of the offering, including the merits and risks involved. Genai Works, Inc. has filed a Form C with the Securities and Exchange Commission in connection with its offering, a copy of which may be obtained here.
The best voice models, now with full orchestration. Build real-time voice and chat agents on one low-latency stack: any LLM, your tools and knowledge, testing, Guardrails, and omnichannel deployment.
OpenAI says one of its models is too good at hacking

OpenAI can no longer rule out that Astra hits the Critical cyber tier of its Preparedness Framework, the top of its own risk scale.
A model gets there if it can find and build working zero-day exploits in many hardened real-world systems with no human involved, or run a novel end-to-end cyberattack against a hardened target given nothing but a goal.
Every previous model, GPT-5.6 Sol included, came in at High.
So OpenAI stopped. Internal work that doesn't meet the new security bar is paused, every agentic use of Astra is monitored with its chain of thought reviewed, and government agencies and outside safety groups are being brought in to test it.
Astra was not the model that got into Hugging Face. OpenAI says that outright.
A frontier lab publicly slowing its own model over cyber risk hasn't happened before.
Anthropic's investors want Dario to stop scaring everyone

The Information profiled Dario Amodei this week, and the quote that travelled came from a large investor who called him more of a religious leader than a CEO.
Anthropic is heading for an IPO. Its CEO keeps telling the public this technology could take an enormous share of entry-level white-collar work.
Staff nickname the internal all-hands the Vision Quest, and the company pays economists to model what happens to GDP and employment if capability keeps compounding.
Calling him a prophet is a way of not arguing with him.
An IPO prospectus has a risk section, and at Anthropic the CEO's public position is the risk. Investors who want quieter language are asking him to disagree with himself in writing.
Cloudflare says humans are becoming a rounding error

Cloudflare CFO Thomas Seifert told investors on Thursday that if trends hold, non-human traffic will be up to 1,000 times human traffic within five years. His phrase was that humans will be a rounding error on the internet.
Not because people browse less. Because machines are growing that fast.
Cloudflare predicted machines would overtake humans in 2027 and got it wrong. It happened in May.
Same day as that call it shipped Kitesurf, a browser for agents. No tabs, no extensions, no themes, no pixel-perfect rendering, because nothing using it has eyes. Cloudflare says it runs on 3 to 7 times less CPU and memory than Chromium.
If half your visitors are already machines, it's worth knowing whether your site reads cleanly to one.
Tool of the Day: Consensus
Consensus searches 250 million peer-reviewed papers instead of the open web. Ask a yes-or-no research question and the Consensus Meter shows how much of the literature agrees, so you get the weight of the evidence instead of the first convincing abstract.
Deep Search writes the search strategy for you, expands your terms and goes looking for studies that contradict each other. Over 170 university libraries partner with it.
Try this yourself:
Ask a yes-or-no question you've argued about, like whether CBT outperforms medication for anxiety, and read the meter before the papers.
Run Deep Search on something contested and look at what it flags as conflicting evidence.
Write filters in plain language, like controlled studies only or since 2020, instead of hunting for checkboxes.
Switch on Medical mode when the answer matters clinically. It narrows to about 50,000 clinical guidelines and 8 million articles from the top 1,000 medical journals.
Who it's for: anyone who has cited a study they only read the headline of.
Everything else you shouldn't miss
Claude Code is switching on automatic approvals: From August 14 auto mode becomes the default for Pro, Max and Team, and Anthropic says its classifier caught 89% of dangerous commands in testing against 14% for manual approval.
The viral SF chatbot is one man with a billboard: ChatTJB's AI stands for Average Individual, meaning artist Tucker Bryant typing every answer himself, and it peaked at 5,000 queries in an hour before he started recruiting volunteers.
Amazon's Texas data center could become America's biggest polluter: The 7.65 GW gas plant powering its Pecos County campus is permitted for 33 million tons of CO2 a year, more than any existing US power plant, though permits sit well above what plants actually burn.
New Orleans put AI on some 911 calls, but not the way it sounds: It only picks up when every human is busy and you're within 200 metres of an incident already reported, it asks whether that's your call, and anything else goes to a person.
Leopold Aschenbrenner bet $400 million on beating ASML: His fund backed Source Foundry, a $5 billion lithography startup founded last year by two Stanford researchers, weeks after a 67% loss forced it to sell most of its public portfolio to Citadel.
Learn more about AI from the experts building it
📸 Follow us on Instagram for fast, visual AI updates in 30 seconds.
📺 Watch us on YouTube to hear insights directly from leading AI voices, builders, and innovators.
🐦 Follow us on X for breaking AI news and real-time industry updates.
🧠 Learn how to build your next AI application with practical resources and expert guidance.




